Impact
This vulnerability is an unsafe deserialization flaw in the sblim-sfcb provider‑manager’s inter‑process communication parsing. When a specially crafted operation header is received, an out‑of‑bounds memory access occurs, terminating the provider‑manager process. The crash leads to a denial of service and may allow limited unintended disclosure of sensitive information. The weakness is identified as CWE‑125.
Affected Systems
The flaw affects Red Hat Enterprise Linux versions 6, 7, 8, 9 and 10.
Risk and Exploitability
The CVSS score is 6.6, reflecting a moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The exploit requires local access; an attacker must be able to send a crafted IPC message to the provider‑manager. Successful exploitation will cause the service to stop, disrupting any processes that rely on sblim‑sfcb, but does not provide broader system compromise.
OpenCVE Enrichment